Junglewise Threat Intelligence

CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVE-2018-17480 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chrome, Google Chromium V8. Vendors: Google.

Executive brief

Google Chromium V8 Engine contains an out-of-bounds write vulnerability triggered during array deserialization. A remote attacker can exploit this via a crafted HTML page to execute arbitrary code inside the browser sandbox.

Affected products

  • Google Chrome prior to 71.0.3578.80
  • Google V8 Engine

Timeline

  • 2018-12-19: disclosed: Initial analysis by NIST
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: exploited: Reported as exploited in the wild

Related threats